Dreams & Stars
Privacy Policy
This policy explains how SkyPact LLC, doing business as Dreams and Stars, handles information for Dreams & Stars. It covers our website, dream reflections, horoscopes, accounts and support. We describe current practices and identify features that are not yet active.
Effective September 13, 2026 · Version 2026-09-13-v41. Who is responsible and how to contact us
SkyPact LLC is the operator and, where that term applies, the controller of the personal information described here. We operate from Florida, United States. Contact support@dreamsandstars.com for privacy requests, consent withdrawal, complaints or questions. This is also our customer-support address.
Our service is intended for adults. A verified email and an age declaration are required for customer dream accounts; this is not identity-document or independent age verification. Our restricted staging environment is separate from our public website. Guest interpretations also require an adult declaration and current Terms acceptance. Email verification is required for account access.
2. Horoscope information and browsing
The horoscope form uses a birth month and day to identify a sun sign and the date you choose for an editorial reading. It does not ask for a name, birth year, exact birth time or birthplace. Form selections are held in the page during use. Sign and reading-date destinations may appear in the URL, browser history and ordinary hosting records.
Horoscope readings currently use original editorial content selected by sign and date; this tool does not send your birth information to an AI interpreter. Hosting and security services receive technical information such as IP address, request time, requested URL, device/browser information and response status to deliver and protect pages.
3. Dream descriptions, AI results and sensitive information
The dream draft stays in the page's memory until you submit it. On submission, our server processes the text, language and request identifier. OpenAI processes the text for automated safety screening and, when allowed, AI generation. A pseudonymous safety identifier accompanies generation requests. We do not keep a separate raw dream submission in our application database or publish submissions.
A completed interpretation may repeat or summarize details from your dream. We keep an encrypted temporary copy for recovery after a connection interruption. Recovery expires after 24 hours; expired copies are removed during routine cleanup, rather than necessarily at the exact expiry second. Treat the result as personal information even though it is encrypted.
Dreams may reveal health, sexual, religious or other sensitive information. Include only what you choose to share. Do not include names, contact details, identification numbers, medical records or identifiable sensitive information about another person. We request explicit consent before processing a dream, including any sensitive information you voluntarily include, for the requested reflection, safety screening and recovery. Our separate Consumer Health Privacy Notice explains health-related information in more detail.
By selecting the separate dream-processing consent checkbox and submitting a dream, you choose to send its text to Dreams & Stars and OpenAI, our AI provider, for automated safety screening and, when permitted, generation of your requested reflection. This includes any health or other sensitive information you voluntarily include. You do not have to include such details to use the dream interpreter. Accepting the Terms alone does not provide dream-processing consent.
4. Accounts, usage and security records
When customer sign-in is available, Clerk handles account identity, email verification and sessions. Our application uses a keyed pseudonymous account identifier to associate age declarations, Terms acceptance, consent records, daily allowances, credit status and activity history. These identifiers are not anonymous merely because they are hashed. The application credit records do not store your raw account identifier or email address; the identity provider still processes account information. For guest use, a signed random browser cookie and a keyed pseudonymous guest identifier associate adult declarations, Terms acceptance, processing-consent receipts, daily allowances, request activity and temporary encrypted result recovery. These records are separate from the verified account allowance; signing in does not transfer guest acceptance to the account. The cookie remembers a browser, not a verified person. These identifiers are pseudonymous, not anonymous.
Request records can include an opaque request identifier, a keyed fingerprint used to detect repeated submissions, status, language and timestamps. Security controls use a signed visitor token and a separate rotating keyed IP-derived identifier. Raw IP addresses are not stored in our application quota database, although hosting/security providers process network information. Operational records include request counts, token use, estimated AI costs and alert status; spending alerts contain no dream text or interpretation.
5. Support and future payments
If you email support, Cloudflare Email Routing forwards the message to our business Google Workspace inbox. We process your address, message, attachments and correspondence to respond and handle requests. Please do not email dream text, medical records, passwords, verification codes or card details unless we establish a necessary secure process with you.
Purchases and checkout are currently disabled. If paid interpretations launch later, we will update the notice and checkout information before collecting payment. A payment processor would handle payment details; relevant order, refund and credit records would be kept for delivery, accounting and dispute resolution. No card details are currently collected by this website.
6. Purposes and legal bases
We use information to deliver the service you request, verify access and allowances, recover completed results, answer support requests, protect accounts, prevent abuse, manage capacity and meet legal obligations. We do not use dream text or personalized interpretations for advertising, cross-site behavioral profiling or session replay. We do not sell personal information, share it for cross-context behavioral advertising, or rent dream datasets.
Where EEA or UK data-protection law applies, necessary account and requested service processing relies on performance of our agreement with you; proportionate security, fraud prevention and administration rely on legitimate interests balanced against your rights; legally required records rely on the relevant legal obligation. We rely on consent for the optional submission and processing of dream content, and explicit consent where it contains special-category information. Optional non-essential tracking, if introduced, will use consent where required. These purposes do not authorize unrelated research, marketing or training use.
You may withdraw consent for future dream processing by stopping submissions and contacting support@dreamsandstars.com. Withdrawal does not invalidate lawful processing already performed. We will address deletion or restriction of remaining information and relevant processor requests, subject to lawful retention exceptions. Horoscope pages and educational guides remain available without dream-processing consent.
7. Who receives information
Cloudflare provides hosting, database, network security and incoming email routing. OpenAI provides dream safety screening and generation. Google Workspace handles support email. Clerk provides customer sign-in; Cloudflare Access protects our separate restricted staging environment, and Turnstile provides bot checks. Providers receive information needed for their functions and may process their own service/security records under their terms. We do not represent that every planned provider feature is already active.
We may disclose necessary information to professional advisers, competent authorities when legally required, or to protect lawful rights and safety. A business transfer may involve information only with applicable safeguards and any required notice or consent. We do not disclose identifiable dream content to another project merely because the same company operates it. External websites have their own privacy practices.
8. OpenAI processing and retention
Generation uses the Responses API with response storage disabled. This setting is not a promise of zero retention: under OpenAI's standard API controls, abuse-monitoring records may contain inputs and outputs for up to 30 days, or longer if legally required. API content is not used for model training by default unless the API account holder opts in. We do not authorize training use of your dream content as part of this service. Different approved controls are not assumed merely because storage is disabled.
9. Retention and deletion
Our operational cleanup targets are: completed-result recovery available for no more than 24 hours; resolved request metadata removed after 30 days; inactive IP-quota records after 7 days; inactive visitor-quota records after 90 days; and dream-processing consent receipts after 90 days. Cleanup runs in batches, so expired information may remain briefly pending deletion. Providers and restricted infrastructure backups follow their own retention schedules and legal requirements.
Account closure removes temporary results and request metadata and attempts deletion of the customer identity account. It does not automatically erase all pseudonymous account, acceptance, credit or financial records. Remaining records are retained only for a continuing purpose such as preventing abuse, honoring non-expiring purchased credits, resolving disputes or meeting legal duties. Requests for broader erasure are reviewed individually; we explain applicable exceptions and retain only what remains necessary. We review support correspondence and residual records for continuing need instead of promising a single period for every category.
A pending request, unresolved payment or unused purchased credits can prevent automatic closure. Contact support for manual resolution; this does not remove statutory deletion rights. Copies you download, email or share are outside our website's control. Backup deletion may follow the backup lifecycle; legal holds or independently required provider records may be retained where lawful.
10. Cookies, browser storage and tracking choices
The first-party ds_visitor cookie contains a signed random token for abuse prevention, is inaccessible to page scripts, and has a 90-day lifetime. Necessary sign-in/security cookies may also be used by configured identity and security providers. The ds_ambient_sound session-storage setting remembers your music preference for the browser session. Dream drafts are not saved in browser storage by this application. This cookie also remembers your guest allowance and supports temporary result recovery.
Live advertising, advertising cookies, third-party marketing analytics and session replay are not currently active. Browser Do Not Track and Global Privacy Control signals therefore do not change an existing advertising profile or sale/sharing practice: we do not carry out those activities. You may clear or block cookies in your browser, although essential sign-in and abuse controls may stop working. Blocking this cookie can prevent guest interpretations and result recovery from working.
Before enabling non-essential advertising or tracking, we will disclose the providers and purposes, offer consent and equally accessible refusal/withdrawal where required, and implement applicable opt-outs and recognized preference signals. Dream text, sensitive inferences and personalized interpretations will not be sent to advertising providers. Reserved ad spaces do not themselves mean that an ad network is active.
11. Privacy requests and complaints
Depending on the law that applies to you, you may request access, correction, deletion, restriction, a portable copy, information about recipients, objection to processing, or withdrawal of consent. You may also have rights concerning sale, sharing, targeted advertising, sensitive information and certain significant automated decisions. We do not use dream reflections to decide legal rights or similarly significant eligibility matters.
Guests can exercise privacy rights without creating an account. Contact support@dreamsandstars.com with relevant available details; we may request proportionate verification to locate and protect your records. Do not send passwords or identity documents unsolicited.
We respond within the period required by applicable law: generally one month for EEA/UK requests and 45 days under many US state laws, with any permitted extension explained within the applicable initial period. We will explain a refusal or limitation and how to appeal it where applicable. To appeal, email the same address with 'Privacy appeal'; you may also complain directly to your local data-protection or consumer authority. We do not retaliate for exercising privacy rights or charge a fee except where the law permits one for a qualifying request.
12. Regional protections
California residents can use the contact above to ask about collected categories, sources, purposes, recipients and retention, and request applicable access, correction or deletion. We do not sell or share information for cross-context behavioral advertising. CCPA and other state-law rights depend on statutory coverage; this notice does not claim a threshold-based law automatically applies or waive rights when it does.
People in other US states, the EEA, UK, Switzerland, Canada, Brazil and other jurisdictions may have additional protections, complaint routes or consent requirements. Mandatory local protections prevail over inconsistent wording. Our Consumer Health Privacy Notice addresses health-related information, including applicable Washington rights. We do not collect biometric identifiers for identity matching or precise location through this service.
13. International processing
We operate in the United States and use providers with international infrastructure. Information may be processed outside your country, where privacy rules and government-access laws can differ. We do not promise that all information remains in your home country or in one geographic region.
Where applicable law requires transfer safeguards, we must use an applicable legal mechanism, such as an adequacy arrangement or approved contractual protections, and any necessary supplementary measures. Contact support for information about the safeguards applicable to your processing. Your use of the site is not treated as blanket consent that replaces legally required transfer safeguards. We may restrict a feature where we cannot lawfully provide it.
14. Children and unintended submissions
Accounts and dream interpretation are intended only for people at least 18 and legally adults where they live. We do not knowingly seek children's personal information. If you believe a child has submitted information or created an account, contact support so we can investigate, restrict access and delete information as required. An age statement does not excuse us from applicable children's privacy obligations.
15. Security and incidents
We use encrypted connections, protected server credentials, access restrictions, input limits, pseudonymous identifiers and encryption for temporary stored results. Security measures reduce risk but cannot guarantee that information will never be lost, misused or accessed without authorization. If an incident requires notice to affected people or authorities, we will provide that notice as required by applicable law.
16. Changes to this policy
The effective date identifies this version. We will update this policy when practices change and provide an appropriate notice before materially new processing, advertising or payment features begin. We will obtain fresh consent where legally required; posting a revision does not retroactively authorize an incompatible use of previously supplied dream information. Contact support for questions about earlier versions.